STIGQter STIGQter: STIG Summary: Tanium 7.0 Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 27 July 2018:

The Tanium Server must be configured to prohibit or restrict the use of organization-defined functions, ports, protocols, and/or services, as defined in the PPSM CAL and vulnerability assessments.

DISA Rule

SV-93391r1_rule

Vulnerability Number

V-78685

Group Title

SRG-APP-000142

Rule Version

TANS-SV-000019

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Submit a formal request to have the Tanium communication ports evaluated and added to the PPSM CAL.

Check Contents

Review the PPSM CAL to ensure Tanium has been registered with all of the TCP ports required for functionality to include (but not limited to) TCP 17472, 17477, 17440, 17441, 443 and 1433.

If any TCP ports are being used on the Tanium Server that have been deemed as restricted by the PPSM CAL, this is a finding.

Vulnerability Number

V-78685

Documentable

False

Rule Version

TANS-SV-000019

Severity Override Guidance

Review the PPSM CAL to ensure Tanium has been registered with all of the TCP ports required for functionality to include (but not limited to) TCP 17472, 17477, 17440, 17441, 443 and 1433.

If any TCP ports are being used on the Tanium Server that have been deemed as restricted by the PPSM CAL, this is a finding.

Check Content Reference

M

Target Key

3215

Comments